ZCyberNews
中文

Articles

460 articles

Aerial view of sugarcane fields and a sugar mill in Queensland, Australia
Industry News

Cyberattack shuts down major Australian sugar mills, disrupting

Mackay Sugar, Australia's second-largest sugar producer, shut down Farleigh and Racecourse mills after a cyberattack halted harvesting in Queensland's Mackay region during crush...

3 min read
Diagram showing AI agent skill audit pipeline comparing declared vs actual behavior across metadata, code, and instructions.HIGH
Malware

Trust No Skill: BIV Audit Finds 80% of AI Agent Skills Misbehave

Unit 42's Behavioral Integrity Verification scanned 49,943 OpenClaw skills and found 80% deviate from declared behavior, with multi-stage attack chains enabling credential theft...

3 min read
Map of the United Kingdom with network nodes and a Chinese flag overlaid, representing telecom security tensions
Industry News

UK Weakens Telecom Security Rules After Industry Lobbying on Salt

Britain dropped requirements for independent signaling intrusion detection and monthly reboots after BT, Vodafone, and others pushed back against proposed telecom security...

3 min readSalt Typhoon
Screenshot of CISA Known Exploited Vulnerabilities catalog entry for CVE-2026-42271HIGH
Vulnerabilities

CVE-2026-42271: LiteLLM Flaw Exploited in the Wild, CISA Adds to KEV

CISA added CVE-2026-42271 (CVSS 8.7) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against BerriAI LiteLLM deployments.

CVE-2026-42271
4 min read
Windows domain controller and Netlogon authentication traffic under active exploitation alert for CVE-2026-41089.CRITICAL
Vulnerabilities

CVE-2026-41089: Windows Netlogon RCE Exploited in Wild

CVE-2026-41089 is a critical Windows Netlogon RCE now reported as exploited in the wild, with Microsoft CNA scoring it CVSS 9.8.

CVE-2026-41089
4 min read
CVE-2026-9082: Drupal Core SQL Injection Bug Added to CISA KEVMEDIUM
Vulnerabilities

CVE-2026-9082: Drupal Core SQL Injection Bug Added to CISA KEV

CISA added CVE-2026-9082 (CVSS 6.5) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against all supported Drupal Core versions.

CVE-2026-9082
3 min read
CVE-2026-20223 (CVSS 10): Unauthenticated API Access in Cisco SecureCRITICAL
Vulnerabilities

CVE-2026-20223 (CVSS 10): Unauthenticated API Access in Cisco Secure

CVE-2026-20223 (CVSS 10.0): Unauthenticated attackers can access internal REST APIs in Cisco Secure Workload with Site Admin privileges. No authentication required.

CVE-2026-20223
3 min read
CVE-2026-2586: Authenticated RCE in GlassFish Admin ConsoleCRITICAL
Vulnerabilities

CVE-2026-2586: Authenticated RCE in GlassFish Admin Console

CVE-2026-2586 (CVSS 9.1) lets authenticated users execute arbitrary OS commands via crafted requests to GlassFish's Administration Console. No patch available as of May 20.

CVE-2026-2586
3 min read
CVE-2026-8957: Mozilla Patches Privilege Escalation in EnterpriseMEDIUM
Vulnerabilities

CVE-2026-8957: Mozilla Patches Privilege Escalation in Enterprise

CVE-2026-8957 (CVSS 6.5) allows privilege escalation in Firefox's Enterprise Policies component. Mozilla fixed it in Firefox 151 and ESR 140.11.

CVE-2026-8957CVE-2026-8956CVE-2026-8950
4 min read
CVE-2026-8959: Firefox Sandbox Escape via Win32 Boundary FlawCRITICAL
Vulnerabilities

CVE-2026-8959: Firefox Sandbox Escape via Win32 Boundary Flaw

CVE-2026-8959 (CVSS 9.6) allows sandbox escape through incorrect boundary conditions in Firefox's Widget:Win32 component. Fixed in Firefox 151, ESR 140.11, and Thunderbird 151.

CVE-2026-8959CVE-2026-8954
4 min read
CVE-2026-4883: Piotnet Forms Plugin RCE via Phar UploadCRITICAL
Vulnerabilities

CVE-2026-4883: Piotnet Forms Plugin RCE via Phar Upload

CVE-2026-4883 (CVSS 9.8) in Piotnet Forms ≤2.1.40 lets unauthenticated attackers upload .phar or .phtml files via an incomplete extension blacklist, enabling remote code execution.

CVE-2026-4883
4 min read
CVE-2026-45230: Unauthenticated Path Traversal in DumbAssets LetsCRITICAL
Vulnerabilities

CVE-2026-45230: Unauthenticated Path Traversal in DumbAssets Lets

CVE-2026-45230 (CVSS 9.1) in DumbAssets through 1.0.11 lets unauthenticated attackers delete arbitrary files via path traversal in the POST /api/delete-file endpoint.

CVE-2026-45230
3 min read
← PrevPage 3 of 39Next →